DVA-C02 Security Practice Question
A developer is using AWS Lambda to process files uploaded to an S3 bucket. The Lambda function needs to read the files and write results to a DynamoDB table. What is the MOST secure way to grant the necessary permissions?
⚠ Common exam trap
DVA-C02 often tests whether candidates confuse resource-based policies (which grant others access to a resource) with execution roles (which grant a compute service access to other resources), leading them to pick a bucket policy instead of an IAM role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM execution role for Lambda with permissions to read from S3 and write to DynamoDB.
The most secure and AWS-recommended pattern is to create an IAM execution role for the Lambda function that grants least-privilege access to the specific S3 bucket and DynamoDB table. Lambda assumes this role at invocation, so no long-lived credentials exist and permissions are centrally managed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach a resource-based policy to the S3 bucket and DynamoDB table allowing access from the Lambda function.
Why it's wrong here
Resource-based policies, such as S3 bucket policies or DynamoDB table policies, define who can access the resource and what actions they can perform. While they *can* be used in the same account, the standard and most secure practice for granting a Lambda function access to other AWS services within the *same account* is through an IAM execution role. Resource policies are more commonly employed for cross-account access or to grant specific permissions to AWS service principals, rather than as the primary mechanism for a Lambda function's operational permissions.
- ✓
Create an IAM execution role for Lambda with permissions to read from S3 and write to DynamoDB.
Why this is correct
An IAM execution role is the recommended and most secure method for granting a Lambda function permissions to interact with other AWS services. When a Lambda function assumes this role, it receives temporary credentials, allowing it to perform actions like reading from an S3 bucket and writing to a DynamoDB table, as defined by the role's attached IAM policies. This approach adheres to the principle of least privilege and eliminates the need for hardcoding or managing static credentials within the function's configuration.
- ✗
Configure the S3 bucket policy to allow the Lambda function's ARN.
Why it's wrong here
While an S3 bucket policy *can* explicitly grant permissions to an IAM principal (like a Lambda function's execution role ARN or a specific user), it defines access *to the bucket itself*, not the permissions *of the Lambda function*. The Lambda function still needs its own identity-based permissions, typically via an IAM execution role, to assume the necessary privileges to make API calls to S3, even if the bucket policy permits it. Relying solely on a bucket policy for same-account access is not the standard or most robust approach for Lambda's operational permissions.
- ✗
Store AWS access keys in the Lambda environment variables.
Why it's wrong here
Storing AWS access keys directly in Lambda environment variables is a highly insecure practice that violates fundamental security best practices. These static credentials could be exposed if the function's configuration is inadvertently leaked or accessed, leading to unauthorized access to AWS resources. Lambda functions are designed to leverage temporary credentials provided by an assumed IAM execution role, eliminating the need to manage or hardcode sensitive access keys, thereby enhancing security and compliance.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.